Skip to content

How to extend CA certficate #430

Answered by chris2511
zuku81 asked this question in Q&A
Discussion options

You must be logged in to vote

So, just create a CA root certificate with the same key.

That's actually the point of the "renewal" option and it does exactly what you described.

The last paragraph is not correct. It is only necessary that all certificates in the chain are valid at the time of verification.
Just tried a renewed CA with different serial-number and later "valid from" date than the server certificate and Firefox did not complain.

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by chris2511
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants
Converted from issue

This discussion was converted from issue #411 on May 24, 2023 16:48.